Moustr/Sprawl Simulatorback to top ↑

Interactive · nothing to fill in · no email required

Most of your AI arrived uninvited. All of it is your responsibility.

Nobody signed off the writing tool in Marketing, the transcription bot sitting on your customer calls, or the AI your vendor switched on in a release note last March. They are running on your data, in your name, today. Answer three questions and see roughly how many there are.

This is a model, not a measurement. It is not based on your organisation and it is not a Moustr finding. It exists so you can see the shape of the problem, and argue with it, before deciding whether to go and look at the real thing.

Nobody knows it's there Someone's noticed We know it's running Someone owns it We can prove it

hover any dot

LIVE MODEL· drag the slider · hover the nodes · edit the maths

A model, not a measurement — not based on your organisation and not a Moustr finding.

1How many people work there?drag it
1,400people
drag me ⟶
501,2502,5003,7505,000
2Have you ever listed your AI?
3What kind of organisation?pick the closest

YOUR RESULT Four of the six questions, answered with your numbers · recalculates as you change anything above
Q1AI SYSTEMS IN USEYOURS

Distinct AI systems the model expects, across all three routes in

Q2NOBODY OWNS THEMYOURS

No name against them if an auditor, a customer or the board asks

Q4A SCAN CAN'T SEE THEMYOURS

Built into software you already own. Only the vendor can tell you

Q6YOU COULD PROVE ITYOURS

Systems you could show a defensible record for today

Take this away as a report.

Two pages: what you entered, what the model produced, what follows if it is roughly right, and every assumption listed so whoever you forward it to can check the arithmetic. No form required.

SAME COMPANY · NEXT STEP You have just modelled the mess. Now look at the instrument.

A ninety-second tour of the product itself — the AI Record, the ownership state against each system, and where the evidence sits. It is a look at the interface rather than a walkthrough of your scenario. No sign-up.

The tour runs on moustr.com itself. Nothing third-party loads.

THE TWO THIS MODEL CANNOT ANSWER Questions 3 and 5 are not arithmetic.

03 · Off the office network, do you see anything? Company networks and set-up devices are covered. Personal devices off them, and some VPN configurations, are outside what we detect. You should hear that from us rather than find it out later.

05 · Has every system got someone with authority to act? Ownership without authority is a name in a spreadsheet. Who can act on a system is a decision for your organisation, not a number this model can produce.

How much of this could you actually answer for?

Every system sits somewhere between "nobody knows it's there" and "we can prove it". The whole job is moving them to the right — and the bar below is what most organisations find when they first look.

Nobody knows it's there Someone's noticed, nobody owns it We know it's running Someone's name is against it We could prove it to an auditor

Internally we call these five stages the assurance ladder. You don't have to.

These are our numbers. Put yours in instead.

Every figure above comes from twelve assumptions we chose, not from your organisation. You almost certainly know better than we do. Change any of them and the estate, the dots and the five stages all recompute as you type.

nothing changed yet — these are all ours
Use my own numbersHide the numbers

These are illustrative planning coefficients, not measurements, and not derived from Moustr customer data. They are deliberately conservative. If one looks wrong for your organisation, change it. That is the point: the argument worth having internally is about the numbers, not about whether the problem exists.

Opens your print dialogue — choose "Save as PDF"

The one measured figure on this page is not ours. 42% of organisations confirmed an AI-related incident in the preceding twelve months and 31% reported a near-miss (Netrio / Censuswide, June 2026). Everything else here is modelled.

THE THREE ROUTES IN

Only one of them goes through IT.

The model is a guess. The register isn't.

Everything above is arithmetic on assumptions you can edit. A thirty-day trial replaces it with your actual estate: agentless discovery of what is running, each system classified with human approval, and a named owner recorded against each one. You find out whether the model was pessimistic or generous.

Request free trial

Agentless by default · read-only · you choose what is included
Moustr does not remediate, block or revoke. It discovers, classifies, assigns ownership and evidences.

Your report is ready.

Everything you have modelled, in two pages you can forward to whoever asks you the question.

What this tool is, and why the numbers are published

Most organisations cannot answer the question "what AI are we running?" — not through negligence, but because nobody planned the estate. It accumulated. The Sprawl Simulator models what that accumulation probably looks like at your size, using twelve planning assumptions that are printed on this page and editable by anyone who disagrees with them.

Why AI estates are larger than organisations expect

AI enters an organisation three ways, and only one of them passes through IT. Bought AI is licensed, procured and on the books — the smallest group and the best documented. Built-in AI is switched on inside platforms already owned, often by a vendor release note, with no procurement record and no decision anywhere. Picked-up AI is what individuals started using because it was faster than waiting for approval. The last two are ordinary behaviour rather than misconduct, and together they usually make up most of the estate.

Why a network scan cannot find everything

AI enabled inside software you already run does not appear on your network as anything new, so no scanning product of any kind will detect it. Only the vendor can declare it. That is why technical discovery has to be combined with what people tell you and what vendors publish, rather than treated as sufficient on its own — a limitation worth understanding before buying any discovery tool, including ours.

Why an inventory is not the same as evidence

A list of systems tells an auditor almost nothing. A record only counts as evidence if it names an accountable owner, states what the system is for and what data it touches, and can be produced on demand without a fire drill. The gap between what an organisation has listed and what it could actually prove is usually the largest number this model produces, and it is the one that costs most to close under deadline pressure.

What the deadline actually is

The nearest pressure is not in the regulation. Enterprise customers already ask about AI governance in security questionnaires, and ISO/IEC 42001 treats an inventory, assigned accountability and an evidence base as preconditions rather than outcomes. Under the EU AI Act, AI literacy duties (Article 4) have applied since February 2025, and obligations for Annex III high-risk systems apply from 2 December 2027. Building those now is inexpensive; reconstructing them under deadline, from an estate nobody has mapped, is not.

What this model is not

It is not a measurement of your organisation and no Moustr system has observed your estate. It is not derived from customer data. It prices nothing and makes no claim about savings or financial exposure. It is not an assessment of compliance with ISO/IEC 42001 or the EU AI Act and should never be shown to an auditor or a regulator as evidence of anything. The one measured figure referenced anywhere on this page is not ours: 42% of organisations confirmed an AI-related incident in the preceding twelve months and 31% reported a near-miss (Netrio / Censuswide, June 2026).